CVE-2022-48069: OS Command Injection
Published Jan 27, 2023
·Updated
Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERYSTRING parameter.
Affected Software
4 affected components
TOTOLINK A830r Firmware=4.1.2cu.5182
TOTOLINK A830R
All of the following
TOTOLINK A830r Firmware=4.1.2cu.5182
TOTOLINK A830R
Event History
Jan 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-48069?
The severity of CVE-2022-48069 is high with a CVSS score of 7.5.
2
How does CVE-2022-48069 affect Totolink A830R V4.1.2cu.5182?
CVE-2022-48069 affects Totolink A830R V4.1.2cu.5182 through a command injection vulnerability via the QUERY_STRING parameter.
3
Is Totolink A830R V4.1.2cu.5182 the only affected software?
No, Totolink A830R V4.1.2cu.5182 is not the only affected software. Totolink A830R V4.1.2cu.5182 Firmware is also affected.
4
How can I fix the command injection vulnerability in Totolink A830R V4.1.2cu.5182?
To fix the command injection vulnerability in Totolink A830R V4.1.2cu.5182, you should update to a secure version of the firmware provided by the manufacturer.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-48069?
The Common Weakness Enumeration (CWE) ID for CVE-2022-48069 is CWE-77 and CWE-78.